Fix critical and high-priority bugs - #8
Merged
Merged
Conversation
- Fix hardcoded 'solid:3000' references in PodService.php comments - Add null safety checks for parse_url() results across multiple methods - Fix Utils::getSolidServerUrl() to construct URL from config components - Add JSON decode error handling in OpenIDConnectClient.php - Improve error messages for invalid WebID formats This commit addresses the following issues: 1. Critical: Misleading hardcoded example in getPodUrlFromWebId() comments 2. High: Missing null/error checks on parse_url() results 3. High: Configuration inconsistency in getSolidServerUrl() 4. High: Unhandled JSON decode failures in retrieve() and loadDPoPKeyPair() All changes maintain backward compatibility while improving error handling and code reliability.
roncodes
added a commit
that referenced
this pull request
Sep 23, 2026
Both sides touched PodService and Utils. PR #8 added parse_url() guards in six places. Two of them were inside the CSS-credential branches this branch deletes -- the service they call was removed in 907664b and never existed at runtime -- so those guards go with the code. The two in getPodUrlFromWebId() and getStorageUrlFromWebId() are kept, and getUserPods() is still covered because it now reaches getStorageUrlFromWebId() rather than parsing the WebID itself. #8's corrected example comments are kept. Utils::getSolidServerUrl() needed more than a textual resolution. #8 fixed it to build the URL from config('solid.server.*') instead of a non-existent solid.server.url; this branch separately taught SolidClient to prefer the host and port an administrator saved through the console. Left as merged, the two would report different servers -- the same class of inconsistency #8 set out to fix. Utils now delegates to SolidClient::serverUrl(), and both it and the instance getServerUrl() go through one private builder, so there is a single answer. phpstan flagged that builder being reached through static:: while private; it is self:: now, and the baseline is regenerated (242 errors, down from 247, since #8's guards replaced some untyped access).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR addresses critical and high-priority bugs identified during a comprehensive code analysis of the Fleetbase Solid extension.
Changes Made
Critical Fixes
http://solid:3000/test/profile/card#metohttps://example-solid-server.com/username/profile/card#meHigh-Priority Fixes
Added null safety checks for
parse_url()resultsgetPodUrlFromWebId()getStorageUrlFromWebId()createPodInStorage()(2 locations)getUserPods()InvalidArgumentExceptionwith descriptive error messages for malformed WebIDsFixed
Utils::getSolidServerUrl()configuration inconsistencyhost,port,secure)solid.server.urlconfigAdded JSON decode error handling
OpenIDConnectClient::retrieve()methodOpenIDConnectClient::loadDPoPKeyPair()methodImpact
Testing
Related Issues
This PR addresses issues identified in the comprehensive bug report, focusing on:
Additional Notes
These fixes improve the robustness of the Solid extension without changing any functional behavior. The changes focus on defensive programming and better error handling to make debugging easier for developers.